Security best practices
Article3 min read
What you should do
- Keep secret keys on your server, in environment variables or a secrets manager. Never in browser or mobile code, URLs, logs, or Git.
- Use one key per server or service, named clearly, so you can revoke one without touching the others.
- Limit live keys to your servers’ IP addresses where you can.
- Roll keys when someone with access leaves, and at least once a year.
- Verify every webhook signature and reject events older than 5 minutes.
- Only request signing links for people your app has already identified.
Caution
Think a key leaked? Roll it right away. The old key keeps working for 24 hours, or revoke it to stop it immediately.
What Notriv does
- Stores only a one-way fingerprint of each key. Nobody, including Notriv staff, can read a key back.
- Asks you to re-enter your password (or an emailed code) before creating or rolling a live key, and emails the account owner every time.
- Refuses keys sent in URLs and slows down addresses that try wrong keys.
- Accepts HTTPS only.
- Keeps test and live data fully separate.
- Signs every webhook with a timestamp, and only delivers to public https:// addresses.
- Records every action on an envelope in its audit trail.
Report a problem
Found a security issue? Email security@notriv.com. Please include the request_id of any request involved.
Was this page helpful?